> For the complete documentation index, see [llms.txt](https://docs.onum.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.onum.com/listeners/listener-integrations/pull-data-from-http-endpoints/pull-data-from-the-pingone-api.md).

# Pull data from the PingOne API

## Overview

Get a list of log events through the [PingOne API](https://docs.pingidentity.com/pingoneaic/tenants/audit-debug-logs-pull.html) using the **HTTP Pull** Listener.

### HTTP Pull Listener configuration <a href="#http-pull-listener-configuration" id="http-pull-listener-configuration"></a>

In Falcon Onum, go to the **Listeners** area and click **New Listener > HTTP Pull**. Give a name to your new Listener and enter the following data:

### Parameters

Add the following parameter:

* **Name** - `tenantEnvFqdn`
* **Value** - Enter your tenant FQDN.

### Secrets

You must define these credentials in Onum:

* `x-api-key` will reference your Ping Identity API Key.
* `x-api-secret` will reference your Ping Identity API Secret.

To do it, click **Add element** and enter a **Name** for the secret (in this case, `x-api-key`). Then, click the **Value** field and select **New secret** to create a new one:

* Give the secret a **Name**.
* Turn off the **Expiration date** option.
* Click **Add new value** and paste the secret corresponding to the value.
* Click **Save**.

You can now select the secret you just created in the corresponding field. Repeat the process for `x-api-secret`.

{% hint style="info" %}
Learn more about secrets in Onum in [this article](/settings/organization-settings/secrets-management.md).
{% endhint %}

### Setup <a href="#setup" id="setup"></a>

After entering the required parameters and secrets, you can choose to manually enter the rest of configuration fields, or simply paste the given YAML:

{% tabs %}
{% tab title="Config as YAML" %}
Toggle **ON** the **Config as YAML** option to enable a free text field where you can paste the following YAML:

```yaml
withTemporalWindow: true
temporalWindow:
  duration: 5m
  offset: 5m
  tz: UTC
  format: RFC3339
withAuthentication: false
withEnumerationPhase: false
collectionPhase:
  paginationType: "cursor"
  cursorSelector: ".pagedResultsCookie"
  initialRequest:
    method: "GET"
    url: "https://${parameters.tenantEnvFqdn}/monitoring/logs"
    headers:
      - name: "Accept"
        value: "application/json"
      - name: "x-api-key"
        value: "${secrets.x-api-key}"
      - name: "x-api-secret"
        value: "${secrets.x-api-secret}"
    queryParams:
      - name: "source"
        value: "am-everything,idm-access, idm-activity, idm-authentication, idm-config,idm-recon,idm-sync"
      - name: "beginTime"
        value: "${temporalWindow.from}"
      - name: "endTime"
        value: "${temporalWindow.to}"
  nextRequest:
    method: "GET"
    url: "https://${parameters.tenantEnvFqdn}/monitoring/logs"
    headers:
      - name: "Accept"
        value: "application/json"
      - name: "x-api-key"
        value: "${secrets.x-api-key}"
      - name: "x-api-secret"
        value: "${secrets.x-api-secret}"
    queryParams:
      - name: "source"
        value: "am-everything,idm-access, idm-activity, idm-authentication, idm-config,idm-recon,idm-sync"
      - name: "beginTime"
        value: "${temporalWindow.from}"
      - name: "endTime"
        value: "${temporalWindow.to}"
      - name: "pagedResultsCookie"
        value: "${pagination.cursor}"
  output:
    select: ".result"
    map: "."
    outputMode: "element"
```

{% endtab %}

{% tab title="Manually configure" %}
**Temporal Window**

Toggle **ON** to add a temporal window for events. This repeatedly shifts the time window over which data is collected.

* **Duration**<mark style="color:$primary;">**\***</mark> - `5m`
* **Offset**<mark style="color:$primary;">**\***</mark> - `5m`
* **Format** - `RFC3339`

**Collection Phase**

* **Pagination Type**<mark style="color:red;">**\***</mark> - `Cursor`
* **Cursor Selector**<mark style="color:$primary;">**\***</mark> - `.pagedResultsCookie`
* **Initial Request**
  * **Response Type**<mark style="color:red;">**\***</mark> - `JSON`
  * **Method**<mark style="color:$primary;">**\***</mark> - `GET`
  * **URL**<mark style="color:$primary;">**\***</mark> - `https://${parameters.tenantEnvFqdn}/monitoring/logs`
  * **Headers**
    * **Name** - `Accept`
    * **Value** - `application/json`
    * **Name** - `x-api-key`
    * **Value** - `${secrets.x-api-key}`
    * **Name** - `x-api-secret`
    * **Value** - `${secrets.x-api-secret}`
  * **Query Params**
    * **Name** - `source`
    * **Value** - `am-everything,idm-access, idm-activity, idm-authentication, idm-config,idm-recon,idm-sync`
    * **Name** - `beginTime`
    * **Value** - `${temporalWindow.from}`
    * **Name** - `endTime`
    * **Value** - `${temporalWindow.to}`
* **Next Request**
  * **Response Type**<mark style="color:red;">**\***</mark> - `JSON`
  * **Method**<mark style="color:$primary;">**\***</mark> - `GET`
  * **URL**<mark style="color:$primary;">**\***</mark> - `https://${parameters.tenantEnvFqdn}/monitoring/logs`
  * **Headers**
    * **Name** - `Accept`
    * **Value** - `application/json`
    * **Name** - `x-api-key`
    * **Value** - `${secrets.x-api-key}`
    * **Name** - `x-api-secret`
    * **Value** - `${secrets.x-api-secret}`
  * **Query Params**
    * **Name** - `source`
    * **Value** - `am-everything,idm-access, idm-activity, idm-authentication, idm-config,idm-recon,idm-sync`
    * **Name** - `beginTime`
    * **Value** - `${temporalWindow.from}`
    * **Name** - `endTime`
    * **Value** - `${temporalWindow.to}`
    * **Name** - `pagedResultsCookie`
    * **Value** - `${pagination.cursor}`
  * **Output**
    * **Select**<mark style="color:$primary;">**\***</mark> - `.result`
    * **Map** - `.`
    * **Output Mode**<mark style="color:$primary;">**\***</mark> - `element`
      {% endtab %}
      {% endtabs %}

When you're done, click **Create labels** to move on to the next step and define the required [Labels](https://app.gitbook.com/o/9sm794iTBacZSmhxRER6/s/kxZeV4nlXcIAjMGZxzLI/the-workspace/listeners/labels) if needed.
